Re: Automatically seeding rand() and mt_rand()
| From: | Alexander Feldman | Date: | Sun, 07 Oct 2001 11:43:52 +0000 |
| Subject: | Re: Automatically seeding rand() and mt_rand() | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-67472@lists.php.net to get a copy of this message | ||
> I have posted this before, but I will try again.
>
> We have once again seen people do silly stuff like this:
>
> srand ((double) microtime() * 1000000);
> $new_id = md5(rand());
> session_id($new_id);
>
> It occurs to me that it is useless to have a rand() function in PHP that
> is not automatically seeded. The rand() function is useless without a
> fairly unique seed, and it is fairly difficult to get a good seed from
It is fairly difficult to get at all random numbers within the PC. It is
possible to make the rand function automatically to call seed if not done
before (the PERL rand does this), however I am not sure that your patch is
enough for this. First of all the random number generator shouldn't be
seeded globally in multithreaded environment (i. e. your rand_seed variable
shouldn't be true global). Otherwise if there are two users calling the same
script in different sessions, the first user can easily predict the "random"
numbers generated by the second. Such behaviour would be security breach.
Better, leave this to the application programmer.
Rgds:
-- Alex
> within PHP. Then you have to add more PHP code to test whether or not you
> have seeded in a previous script.
>
> If, in ext/standard/rand.c one were to add a global variable: "rand_seed"
> set to zero. In the function php_srand, keep it updated, and in php_rand
> check if it is zero, if so call php_srand() with the results from:
> GENERATE_SEED(); to update the random seed. A great deal of programming
> atrocities can be avoided, and rand() will, in fact, be more random.
>
> This is the patch I want to commit:
>
> --- oldrand.c Sun Oct 7 07:12:59 2001
> +++ rand.c Sun Oct 7 07:11:58 2001
> @@ -38,6 +38,7 @@
>
> #include "basic_functions.h"
>
> +long rand_seed = 0;
>
> /* SYSTEM RAND FUNCTIONS */
>
> @@ -45,6 +46,7 @@
> */
> PHPAPI void php_srand(long seed TSRMLS_DC)
> {
> + rand_seed = seed;
> #ifdef ZTS
> BG(rand_seed) = (unsigned int) seed;
> #else
> @@ -328,6 +330,10 @@
> if (argc != 0 && zend_parse_parameters(argc TSRMLS_CC, "ll",
> &min,
> &max) == FAILURE)
> return;
>
> + if(rand_seed == 0) {
> + long seed = GENERATE_SEED();
> + php_srand(seed TSRMLS_CC);
> + }
> number = php_rand(TSRMLS_C);
>
> if (argc == 2) {
>
>
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>